Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
26 February 2026
Cybersecurity researchers have disclosed details of a new malicious package discovered on the NuGet Gallery, impersonating a library from financial services firm Stripe in an attempt to target the financial sector.
The package, codenamed StripeApi.Net, attempts to masquerade as Stripe.net, a legitimate library from Stripe that has over 75 million downloads. It was uploaded by a user named